We take security seriously. Here's how we protect your data and maintain the trust you place in us.
All sensitive data including access tokens, customer information, and passwords are encrypted using AES-256-GCM encryption with unique initialization vectors for each record.
All data transmitted between your browser and our servers is encrypted using TLS 1.3 with modern cipher suites.
Database backups are encrypted using the same standards as production data and stored securely with access controls.
We implement strict role-based permissions:
All customer data is isolated by workspace. Users can only access data from workspaces they belong to.
Minimum 8 characters required. All passwords are hashed using bcrypt with salt rounds before storage.
Our application is hosted on enterprise-grade cloud infrastructure (Railway/AWS) with:
We use managed PostgreSQL databases with:
We maintain completely separate development, staging, and production environments. Test data never touches production systems.
We comply with the General Data Protection Regulation (GDPR) for EU users, including:
We comply with the California Consumer Privacy Act, including the right to know, delete, and opt-out.
As a Shopify app, we meet all Shopify security and privacy requirements, including Protected Customer Data access controls.
We adhere to Meta's Tech Partner Security Requirements, including strict data isolation, encryption standards, and regular security assessments to protect user data shared via our platform integrations.
We have a documented security incident response policy that includes:
pages.security.section5.subsection2.content
pages.security.section5.subsection2.response
We retain customer data only as long as necessary to provide our services:
When data is deleted, it is permanently removed from our production databases and cannot be recovered. Backup data is automatically purged according to our retention schedule.
We carefully vet all third-party services we integrate with:
All third-party services sign data processing agreements and comply with applicable privacy regulations.
We're committed to transparency about our security practices. If you have questions or concerns:
Security Team: security@zellio.ai
General Support: support@zellio.ai
Privacy Inquiries: privacy@zellio.ai
Last Updated: October 26, 2025
© 2025 Zellio AI. All rights reserved.